Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

629 results about "Data breach" patented technology

A data breach is the intentional or unintentional release of secure or private/confidential information to an untrusted environment. Other terms for this phenomenon include unintentional information disclosure, data leak, information leakage and also data spill. Incidents range from concerted attacks by black hats, or individuals who hack for some kind of personal gain, associated with organized crime, political activist or national governments to careless disposal of used computer equipment or data storage media and unhackable source.

Data leakage prevention method and system based on user behavior perception

The invention relates to the technical field of network security and data protection, and discloses a data leakage prevention method and system based on user behavior perception, and the method comprises the steps: obtaining historical operation data, and constructing a personalized behavior reference library; monitoring a current access behavior in real time by sliding a time window, calculating a deviation degree and triggering anomaly detection; performing multi-level feature analysis on the abnormal behavior and calculating a comprehensive abnormal score; dynamically adjusting the access authority according to the score, recording an abnormal behavior and carrying out relevance matching; optimizing the reference model through feedback learning; and evaluating the credibility and the risk level based on an accurate modeling result, and adaptively adjusting permission configuration. According to the method, the user behavior rule can be accurately captured, the data leakage risk can be efficiently identified, the access permission can be dynamically adjusted, the false alarm rate can be reduced, adaptive protection can be realized, and data security and business smoothness can be guaranteed.
Owner:SHANGHAI WICRESOFT

Maritime accident prediction method and device based on interpretable integrated machine learning

The invention discloses a maritime accident prediction method and device based on interpretable integrated machine learning, and relates to the technical field of maritime affair safety risk analysis, and the method comprises the steps: obtaining accident investigation data, carrying out the preprocessing, balancing the data through a ten-fold layered oversampling method, and carrying out the cross verification training, and determining a performance optimal model by using the test set and carrying out interpretable analysis to explain the influence of the characteristics on the accident prediction result. By constructing a closed-loop'data processing-model optimization-explanation output 'process and adopting SMOTE oversampling and ten-fold layered cross validation training and a heterogeneous base model ensemble learning strategy, the processing capacity of the data imbalance problem of accident categories is improved, the data leakage problem of oversampling is avoided, and the possible bias of a single model is overcome. The interpretability analysis of the model prediction result can quantitatively display the contribution degree of each feature to prediction globally and locally, reveal the nonlinear relationship and interaction effect between the features, and provide transparent interpretation of model decision.
Owner:TIANJIN UNIVERSITY OF TECHNOLOGY

Enterprise-level large model agent application system supporting multi-modal collaboration

The invention relates to the technical field of artificial intelligence, and discloses an enterprise-level large-model agent application system supporting multi-modal collaboration, and the system comprises a user interaction terminal, an agent engine server, a knowledge engine server, a plug-in integration center, and a distributed storage unit. The agent engine server is responsible for intention recognition and task arrangement of a multi-modal input signal, and dynamically loads a differential reasoning strategy based on an environment isolation mechanism. And the knowledge engine server constructs a cross-modal semantic anchor point, analyzes an unstructured document into a tetrad knowledge unit, and realizes accurate recall of images and texts by using a hybrid retrieval algorithm. And the plug-in integration center executes outbound replacement and inbound restoration of the sensitive data through the context-aware dynamic desensitization gateway. According to the method, through a multi-modal semantic association and closed-loop verification mechanism, the problems of low complex document retrieval precision and leakage of external calling data are solved, and the service processing capacity and safety of the system are improved.
Owner:LINGRUIDA (XIAMEN) TECHNOLOGY CO LTD

Data security protection system and method based on multi-dimensional factors

The invention belongs to the technical field of data security, and particularly relates to a data security protection system and method based on multi-dimensional factors. Comprising a user analysis module, an environment risk analysis module, a data sensitivity grading module, a behavior analysis module, a risk assessment module and a decision execution module. The method has the beneficial effects that aiming at the defects of a traditional static permission model, a dynamic risk assessment system is constructed by fusing user identity, behavior pattern, access context and environment security four-dimensional features in combination with reinforcement learning weight optimization, and the problem that the permission cannot be adjusted in time when the user behavior is abnormal is solved; according to the method, the problems that multi-dimensional information such as environment, behavior and data sensitivity is not fused, data leakage or unauthorized access risks cannot be recognized in real time and the like are solved, sensitive data exposure risks can be effectively reduced, meanwhile, the problem that a static permission model cannot respond to behavior / environment changes in real time is solved, and enterprise data security is improved.
Owner:RES INST OF NUCLEAR POWER OPERATION

Cloud AI data leakage risk prediction and management and control method and system based on flow map

The invention provides a cloud AI data leakage risk prediction and control method and system based on a flow map, and relates to the technical field of cloud computing data security. Based on the collected multi-source log data, constructing a time series data flow knowledge graph; inputting the knowledge graph into a space-time diagram risk prediction model, and obtaining a dynamic risk score of an entity and a predicted potential data leakage path by fusing a space-time diagram neural network and risk conduction simulation; according to the dynamic risk score and the potential data leakage path, gradient dynamic security management and control measures are generated and executed, and the measures comprise differentiated access control actions triggered according to the risk level; and generating a visual audit report of the data access link based on the risk prediction result and the security management and control process. Through a time sequence graph reflecting dynamic flow of data and utilizing STGNN to carry out risk conduction modeling and prediction, the active defense capability of cloud AI data security is improved, the accuracy of risk identification is effectively improved, and service interference is effectively reduced.
Owner:INFORMATION COMM COMPANY STATE GRID SHANDONG ELECTRIC POWER

Fault diagnosis method for conveying belt

The invention provides a fault diagnosis method for a conveying belt. The fault diagnosis method comprises the steps that vibration data, pressure data and temperature data in the belt running process are collected through a sensor module; carrying out denoising processing on the collected vibration data, pressure data and temperature data, and removing abnormal values; feature parameters are extracted from the data subjected to data preprocessing; the extracted feature parameters are uploaded to a private cloud server through an Internet of Things module, and a lightweight algorithm is adopted to analyze the feature parameters; according to the analysis result of the lightweight algorithm, a preset fault threshold value is matched, and the fault type of the belt is output. According to the method, multi-source data fusion and targeted feature extraction are adopted, the fault false alarm rate is reduced to 10% or below, industrial data leakage is avoided through private cloud deployment, and the deployment cost is reduced by 60% compared with public cloud; based on a sensor and an open source tool, deployment can be completed within 30 days without professional teams, and belt conveyors in different scenes such as mine underground and logistics sorting can be adapted.
Owner:ZHONGLUAN TECH CO LTD +1

V2G service-oriented multi-granularity data on-demand sharing security aggregation method

The invention provides a V2G service-oriented multi-granularity data on-demand sharing security aggregation method, and relates to the technical field of data security. The method comprises the following steps: acquiring multi-dimensional and multi-granularity power utilization data interacted between an electric vehicle and a power grid, and obtaining compressed data of each dimension based on super-incremental sequence compression; summing and aggregating the compressed data in the jurisdiction of the charging station, and obtaining an encrypted aggregation result by adopting Paillier homomorphic encryption; when a user accesses, a request is verified through an access authorization judgment function constructed by an RBAC model, and ciphertext aggregation (homomorphic addition is executed on global data, and differential ciphertext operation is executed on single-pile data to construct single-pile encrypted data) is executed as required after verification is passed; a complete decryption result is obtained through collaborative decryption by adopting a threshold decryption mechanism, and then target power consumption data is obtained through super-incremental sequence decoding. According to the method, on-demand access of multi-granularity data is realized, transmission overhead is reduced, data leakage and unauthorized access are completely eradicated through double guarantee of permission and encryption, and V2G multi-scene requirements are met.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +4

Delegate data leakage protection using self-generated task-specific security policies

ActiveUS12513189B1Securing communicationInteraction agentSecurity policy
Techniques for delegate data leakage protection using self-generated task-specific security policies are described. An interaction agent obtains a request to have the interaction agent perform a task (e.g., on behalf of a user) that involves interacting with an untrusted entity. The interaction agent generates a task-specific security policy via use of first machine learning (ML) model, applies the security policy for the execution of the task, and executes the task based on use of the ML model to identify actions to be performed for the task. The security policy governs which of the actions the interaction agent can perform or cannot perform during the execution of the task.
Owner:AMAZON TECH INC

Data flow tracing method for data security event and data entity mode

The invention relates to a data circulation traceability method of a data security event and a data entity mode, and aims to solve the technical problems that the similar technology in the existing digital power grid lacks the technical combination of block chains, Internet of Things and meta universe and the big data and AI artificial intelligence technology. The method is characterized in that a unified operation interface of the method is provided with a digital twinborn body generated and constructed by a meta-universe technology as a data flow traceability model, edge intelligence of a digital power grid is accessed, when data in the edge intelligence of the digital power grid is abnormally tampered, the CNN discovers data abnormity, the intruded edge intelligence is accurately positioned, and the data flow traceability of the digital power grid is realized. The range of the abnormal behavior is predicted; meanwhile, pressure testing and virtual deduction are immediately carried out in a digital twinborn body formed by the meta universe technology, a possible data security event of system crash or data leakage is predicted, an accurate disposal scheme and risk level division are given in advance, and low-level risks are autonomously handled.
Owner:GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Large model privacy reasoning method and device based on trusted hardware and electronic equipment

The invention relates to the technical field of security calculation and privacy protection, in particular to a large model privacy reasoning method and device based on trusted hardware and electronic device.The method comprises the steps that before a large model reasoning task is executed, a client and a server initialize respective pseudo-random number generators based on information interaction so as to synchronize initial seeds, and the pseudo-random number generators are initialized; generating a random number based on the seed; in the reasoning execution process, homomorphic encryption is used for completing word embedding of large model reasoning, a reasoning instruction set is used for converting all operators into instruction combinations, privacy reasoning is carried out based on a privacy reasoning protocol and a random number generated by a pseudo-random number, and the random number is used for masking privacy data; and after the task is completed, obtaining an execution result and proof information provided by the server, performing verification, and refusing to receive the result if verification fails. Therefore, the problems of data leakage risk, difficulty in considering safety and efficiency and the like existing in related technologies are solved.
Owner:TSINGHUA UNIVERSITY

Security authentication multi-start method for Linux system of development board

The invention discloses a development board Linux system security authentication multi-start method, which comprises the steps of 1, hardware trust root initialization and storage area division, 2, hardware trust root self-inspection and measurement, 3, starting item dynamic loading and multi-stage authentication, 4, security context establishment and system switching, and 5, multi-system isolation and collaboration. Step 6, performing security audit and exception handling; full-link authentication is realized by taking a hardware trust root as an anchor point, malicious mirror startup and inter-system data leakage are effectively resisted in combination with a storage and resource isolation mechanism, scenes such as on-demand dynamic switching, flexible adaptation debugging, upgrading and fault recovery of multiple systems can be realized, and the system reliability is improved by optimizing the lightweight design of an authentication algorithm and resource management. Limited computing power of the development board is adapted, the starting process and abnormal events can be completely recorded, and illegal operation can be traced conveniently.
Owner:BEIJING XUNWEI ELECTRONICS CO LTD

System and method for preventing data leakage by realtime native fingerprinting inside a cloud storage

PendingUS20260073067A1Digital data protectionEndpoint securityCloud storage
The present disclosure provides a system and a method for performing real-time cloud-native fingerprinting and managing sensitive content within a cloud storage platform to prevent data leakage. The system comprises a cloud storage platform comprising a data leakage prevention (DLP) server. The DLP server configured for receiving and storing a sensitive document, receiving a sensitivity level of the sensitive document, fingerprinting the sensitive document based on the sensitivity level, indexing and storing the fingerprint, sharing the fingerprint to an endpoint security agent, receiving leak indication, performing leak analysis and notifying the leak to a document owner. The system and method further perform monitoring of the sensitive data that has been fingerprinted and stored under a security folder, for a predefined time and automatically moving the sensitive data from the security folder after the predefined time.
Owner:SHRIVASTAVA VIKALP

Preservation of network integrity in changing network conditions triggered by data harvesting for retrospective decryption

ActiveUS20260058985A1Securing communicationNetwork conditionsNetwork integrity
A method for enhancing security of data, code, and / or network components by introducing a layer of integrity management that adapts to changing conditions within a network. The method may include use of a processor to perform intrusion analysis using an intrusion detection system and / or prevention system, behavioral analysis by accessing user logs to see if behavior is within a normal range, and / or geolocation analysis to see if the piece of data, section of code, and / or network component are within their usual surroundings. When there is a concern of a data breach, leak, and / or hack, the processor may initiate a response that detects other pieces of data, sections of code, and / or network components in proximity, initiates a self-destruct mechanism, triggers hardware to perform outside of operational specifications, and contains the spread of the data breach, leak, and / or hack through shutdown procedures, isolating affected systems, and / or alerting security personnel.
Owner:BANK OF AMERICA CORP

Multi-port network interface card (NIC)

Systems, methods, and apparatuses disclosed herein can enable a computing system to connect to a network. These systems, methods, and apparatuses can connect the computing system to the network through multiple network connections. These multiple network connections represent distinct, physically separate signal pathways to improve security. This physical separation, or isolation, from one another creates distinct boundaries between these multiple network connections, for example, to minimize shared resources these systems, methods, and apparatuses. These distinct boundaries can reduce the vulnerability of these systems, methods, and apparatuses to, for example, attacks that exploit shared sources among these systems, methods, and apparatuses, data leakage within these systems, methods, and apparatuses, and / or unauthorized access to these systems, methods, and apparatuses. Moreover, these distinct boundaries can additionally enhance security by improving fault isolation, enforcing access control, and / or supporting secure communication protocols, among others, within these systems, methods, and apparatuses.
Owner:OWL CYBER DEFENSE SOLUTIONS LLC

Multi-level tenant management method

PendingCN121478551AError detection/correctionExtensible architectureAuthorization
The invention provides a multi-level tenant management method. A tree-shaped hierarchical structure with a root tenant as a vertex is constructed, dynamic association of sub-tenants and automatic increasing of hierarchical depth values are realized by utilizing parent tenant identifiers, and a depth-extensible architecture is constructed as required. The root tenant independently configures the function permission and the resource permission for each sub-tenant, and a rigid mechanism depending on a static strategy table or a fixed permission distribution mode is replaced. Meanwhile, by binding an attribution tenant identifier for a system resource and clearly distinguishing the resource attribute as a private resource or a controllable resource, dual verification based on a hierarchical relationship and the resource attribute can be carried out, a resource boundary between tenants is implemented at a resource access source, the risk of data leakage caused by no isolation of a shared storage pool mode is solved, and the system performance is improved. And the problem of low efficiency caused by manual configuration required by cross-level collaboration in a physical resource direct binding mode is solved, so that efficient and safe resource collaboration operation within an authorization range is supported while data security isolation is guaranteed.
Owner:GUANGZHOU DINGJIA COMPUTER TECHNOLOGY CO LTD

Data security protection method, device, system, security control framework, and storage medium

A data security protection method, device, system, security control framework and storage medium. A protection module is arranged on the target device to control the read / write permission of the computer device on the storage device, so as to ensure the communication security between the storage devices, avoid the computer security risk caused by the malicious storage device accessing the computer device, and avoid the data leakage of the storage device caused by the computer device maliciously accessing the data of the storage device. Based on the current protection mode of the target device, the data interaction instruction sent by the computer device is controlled.
Owner:HUANG JIANBANG

System and method for pre-emptive detection of email impersonation and man-in-the-middle attacks using ai-driven telemetry and data leak prevention remediation

Disclosed is a system and method for pre-emptive detection, attribution, and reversal of outbound data leaks and impersonation-based attacks occurring beyond traditional enterprise endpoint security boundaries. An outbound instrumentation gateway may insert telemetry identifiers into outbound electronic communications, enabling persistent tracking of message interactions within external or third-party domains. A RAPTORAI analytics engine may process metadata collected from these interactions using a multi-stage artificial-intelligence pipeline that combines predictive anomaly modeling and large-language-model (LLM) attribution. When anomalous or malicious behavior is detected, a Double DLP remediation engine may be activated, which is capable of pausing, auto-locking, or revoking message access after transmission but before compromise. A PRE-Crime telemetry layer provides visibility into early-stage reconnaissance activities by threat actors operating beyond the endpoint, thereby reducing mean time to detect (MTTD) and mean time to respond (MTTR) to effectively zero. Administrative dashboards present live analytics of third-party risks, reconnaissance indicators, and auto-remediation events.
Owner:KHAN ZAFAR

Data watermark embedding and tracing method based on zero-width character

The invention belongs to the technical field of data watermarks, and particularly relates to a zero-width character-based data watermark embedding and tracing method, which comprises the following steps of: reading a system identifier, to-be-added watermark data and an identity identification number of a corresponding access user; generating watermark information according to the access user identity identification number, the data access timestamp and the system identifier; adopting zero-width characters to encode the watermark information to obtain an encoded zero-width character sequence; splitting the coded zero-width character sequence into a plurality of subsequences based on the identity identification number of the user to obtain a complete subsequence set; and analyzing the to-be-added watermark data, determining to select a corresponding number of embedding positions in the to-be-added watermark data, and embedding the subsequences into the to-be-added watermark data. According to the method, the watermark information and the user identity are strongly bound, unique binding of the watermark, a specific user and an access scene is realized, and a data source can be accurately positioned during data leakage traceability.
Owner:HANGZHOU SHENPU TECH CO LTD

Unmanned aerial vehicle data sharing method and device based on privacy protection

The invention discloses an unmanned aerial vehicle data sharing method and device based on privacy protection, and the method comprises the steps: collecting flight data, environment perception information and task state data through an unmanned aerial vehicle, combining an operation instruction, scheduling information and user authority data of a ground control end, and intelligently recognizing to-be-shared privacy data. According to the data type and the sensitivity level, the system performs protection processing on the sensitive data by adopting a privacy computing technology such as homomorphic encryption or differential privacy, generates protected data and uploads the protected data to a sharing platform through a secure channel. The platform directly executes cooperative calculation and analysis on the protected data without decryption, generates an intermediate result, and feeds back the intermediate result to a related terminal after inverse processing. The risk of data leakage caused by calculation after decryption in a traditional encryption scheme is solved, the high-efficiency multi-party cooperative calculation capability is maintained while absolute security of sensitive information is guaranteed, and a solution which gives consideration to privacy protection and data value mining is provided for an unmanned aerial vehicle system.
Owner:SHANDONG CHAOYUE DATA CONTROL ELECTRONICS CO LTD

Community data sharing and exchanging security control method based on block chain

The invention belongs to the technical field of data security, and particularly relates to a community data sharing and exchanging security control method based on a block chain, which realizes fine-grained and dynamic access control by performing refined permission division on user characteristics and data attributes and constructing a verifiable attribute permission mapping relationship in an intelligent contract. The slave logic layer prevents unauthorized access vulnerabilities; a mode of combining a fully homomorphic encryption algorithm and a lightweight homomorphic encryption algorithm is adopted, direct operation of data in an encryption state is realized, a permission verification mechanism without data content leakage is constructed in combination with zero-knowledge proof, and dual protection of'calculation without decryption and verification without leakage 'is formed. According to the method, the data leakage risk caused by smart contract code vulnerabilities is fundamentally immunized, an extensive permission allocation mode is broken through by an attribute-based permission management method, refined permission division can be performed according to actual attributes of users and data, permission abuse and unauthorized access are effectively avoided, and the normalization and security of data access are greatly improved.
Owner:CETC BIGDATA RES INST CO LTD

Supermarket cash register data real-time processing and privacy protection method based on edge computing

The invention discloses a supermarket cash register data real-time processing and privacy protection method based on edge computing. According to the invention, through edge node localization training and a gradient parameter sharing mechanism, the data transmission pressure of a central node is obviously reduced, the convergence speed of a global model is effectively improved through a dynamic weighted aggregation algorithm, the iteration period of a transaction risk control model is greatly shortened, and the response delay of a system to abnormal transactions is controlled at an extremely low level; a high-concurrency transaction scene can be efficiently processed, the real-time detection capability and the system stability are enhanced, a differential encryption strategy is implemented for data with different sensitivities by a hierarchical privacy protection architecture, the unpredictability of a core data key is ensured by quantum random number encryption, a dynamic differential privacy algorithm automatically adapts to data distribution characteristics when noise is added, and the real-time detection capability and the system stability are improved. A hardware security module is combined with a threshold secret sharing mechanism, and a multi-layer protection system is constructed from a physical layer to a protocol layer, so that the risk of data leakage is effectively reduced, and meanwhile, the compliance requirements of related laws and regulations are met.
Owner:GUANGZHOU CHAOYING SOFTWARE ON CO LTD

Intent-aware data leak mitigation

A data flow is intercepted, the intercepted data including a set of data fields carrying a corresponding set of content. An intent is identified behind a transaction including the intercepted data. A conformity indication is set relative to a first data field in the set of data fields to indicate nonconformity of a first content of the first data field, the setting including comparing the first content with expected data corresponding to a mapping of the intent in a knowledge graph. Based on the conformity indication, the first content is modified to form modified content. In the transaction in the data flow, the first content is replaced with the modified content, the replacing forming a modified transaction. The modified transaction is transmitted to a receiver data processing system over a data integration channel.
Owner:US BANK NATIONAL ASSOCIATION

Data leakage real-time blocking method fusing micro-isolation strategy and context awareness

The invention relates to the technical field of network security, and discloses a data leakage real-time blocking method fusing a micro-isolation strategy and context awareness. According to the method, a micro-isolation strategy engine based on a data sensitivity level is constructed, a logic security domain is defined, and an independent access control rule is configured; collecting a network data flow in real time, identifying sensitive data by using a deep packet detection technology, and extracting context information; dynamically analyzing and generating risk metadata, calculating a real-time risk index, and establishing a behavior baseline model to detect behavior deviation; in combination with behavior deviation, a risk index and a data operation type, an access control rule is adaptively decided and dynamically updated, a high-risk or unauthorized data transmission session is blocked in real time, and the data leakage protection capability is improved.
Owner:JIANGSU MR ZHI INFORMATION TECH CO LTD

Dynamic adjustment method and device for user permission, equipment and medium

The invention provides a user permission dynamic adjustment method and device, equipment and a medium, and the method predicts a target permission required by a target service based on a permission prediction model and a target service context vector when a service change instruction is detected. And on the basis of the permission prediction model and the target user behavior sequence, the real-time permission demand of the user and the confidence coefficient corresponding to the user behavior risk are predicted, so that the permission prediction accuracy is improved, and the data leakage risk is reduced. Based on the current permission of the target user and the target permission set, the user does not need to perform manual application and approval, and the approval of the incremental permission is automatically generated, so that the permission adjustment operation is simplified, and the permission adjustment efficiency and the adjustment accuracy are improved. The method can be applied to authority approval nodes in the financial business field or the medical pension field, so that the authority approval efficiency and accuracy are improved.
Owner:CHINA PING AN PROPERTY INSURANCE CO LTD

Image recognition method for end, edge and cloud layered federal learning based on knowledge distillation

The invention discloses an image recognition method based on end, edge and cloud layered federated learning of knowledge distillation, which is characterized in that original data or full-quantity model parameters are replaced by transmitting embedded vectors, a synthetic sample is combined to serve as a knowledge carrier, the communication traffic is reduced by more than 60% compared with the traditional federated learning, and the image recognition method is adaptive to mass equipment concurrent scenes. In the training process, original data are only locally converted into vectors and never leave end equipment, so that the risk of data leakage is avoided from the source, and the requirements of privacy protection laws and regulations are met. By introducing a knowledge distillation method and hierarchical model deployment (end side light weight and cloud side high performance), equipment with different computing power can participate in cooperative training, and the problem of computing power resource mismatching is solved. Meanwhile, a Logs-based sample screening mechanism and multi-dimensional structured loss (and) are innovatively combined, and compared with existing schemes such as FedAvg and FedAgg, the method has the advantages that the test accuracy is remarkably improved, and particularly, the advantages are more outstanding in a high data heterogeneous scene.
Owner:HEBEI UNIV OF TECH

Method and system for credible exchange of enterprise data on supply chain

The invention discloses a credible exchange method and system for enterprise data on a supply chain, and relates to the technical field of enterprise data exchange, a credible interaction verification module is arranged on a data terminal of each enterprise on the supply chain, and a plurality of credible interaction verification modules are numbered; and a data relay server is arranged. A trusted interaction verification module executes a data trusted exchange multi-party verification mechanism to verify the legality and security of a data interaction request; at least three-party cross verification is adopted, a credible interaction verification module corresponding to a number verifies the legality and security of a data interaction request enterprise server based on network address communication and interaction ciphertext of a data interaction request, and the risk of data leakage caused by directional communication cheating specially set based on a target enterprise is avoided; after a credible exchange multi-party verification mechanism is passed, a safer enterprise data credible exchange method on the supply chain is constructed, and safe interaction of supply chain data is ensured.
Owner:SHANGHAI HUAFENG CHUANGXIANG INTERNET TECH CO LTD

Data full-process monitoring and early warning method in vehicle network interaction scene

The invention provides a data full-process monitoring and early warning method in a vehicle network interaction scene, and relates to the technical field of vehicle network interaction. Threat intelligence and public vulnerability information oriented to a vehicle network interaction platform are associated with identified network assets, modeling is carried out on traffic, power and time sequence characteristics in the processes of vehicle network charging, load prediction and energy interaction, dynamic comparison is carried out on data streams, and risk behaviors in the communication process are found; illegal access, data leakage and transverse attack paths are identified, and a structured attacker portrait is formed; abstracting system assets and data streams into a graph model with probability and time weight, and screening out feasible attack routes; and finally, performing multi-round attack simulation on the selected route based on a domain meta-attack language to obtain global compromise time TTC and contribution degrees of all technologies, and using the contribution degrees to enhance detection rules and processing priorities. And if abnormal traffic or suspicious interaction is monitored, giving risk early warning, and performing automatic disposal according to a set strategy.
Owner:NORTHEASTERN UNIV CHINA +4

Secret communication system and method for operation and maintenance service management based on block chain technology

The invention belongs to the technical field of operation and maintenance secret communication, and particularly relates to a secret communication system and method for operation and maintenance service management based on the block chain technology, and the system comprises a three-layer data framework which comprises an operation and maintenance layer, a data center layer and a block chain layer, the operation and maintenance layer is used for storing operation and maintenance service data, operating an operation and maintenance system and a communication system, and outputting full data fragments to be encrypted and stored to the operation and maintenance layer; and a cross-layer transmission control module and a block chain encryption recording module. According to the invention, the confidentiality and security of data communication in operation and maintenance service management can be improved, data leakage and illegal access are effectively prevented, data exception is handled, the security protection capability of the system is improved, and potential risks are avoided.
Owner:JIANGXI PROVINCIAL TRAFFIC MONITORING & COMMAND CENT +1

Collective leakage detection in retrieval augmented generation (RAG)

PendingUS20260119651A1Platform integrity maintainanceNear neighborNearest neighbor clustering
A collective data leakage attacks on a Retrieval-Augmented Generation (RAG) application for a generative artificial intelligence (GenAI) application is detected and prevented based on an analysis of incoming queries to distinguish normal and potentially malicious querying behavior. Similarity distances associated with each query are determined, such as the distances between the query vector embeddings and the nearest neighbors in the vector embedding space, distances between each query vector embedding and other query vector embeddings for other queries from the same user, or distances between each query vector embedding and the nearest neighbor cluster of vector embeddings in the vector space. A data leakage attack on the RAG application may be determined based on the similarity distances associated with each query. In response to the identification of a potential data leakage attack, the release of data from the RAG application may be halted.
Owner:INTUIT INC

Digital media asset management method and system

The invention relates to the technical field of digital media asset management, in particular to a digital media asset management method and system, which comprises the processes of metadata compliance tag injection, policy awareness mixed query and privacy affinity cache management. A cross-cloud query path is dynamically decided through an intelligent metadata gateway, double cloud caches are deployed in a hierarchical manner, and label consistency and copyright transaction security are ensured by using a block chain evidence storage module. According to the method, the global retrieval efficiency can be improved, the sensitive data cross-border transmission risk is reduced, illegal access and data leakage are effectively avoided, meanwhile, the high-frequency sensitive data retrieval performance is optimized by dynamically adjusting the cache strategy, and efficient cooperation of cross-layer events is achieved. The invention provides a digital media asset management method and a digital media asset management system, and aims to solve or at least alleviate the problems of low metadata retrieval efficiency and sensitive data cross-border transmission compliance risk coexistence in a mixed cloud environment.
Owner:大河传媒有限公司